Skip to main content
Trust · Security

How we secure the platform that secures you.

A platform that holds every organisation's external exposure in one place is a uniquely attractive target, and we would rather set out the controls than assert that we take security seriously. This page describes how ShadowMap is built, hosted, accessed, monitored and eventually deleted.

Send the questionnaire. We answer it.

DPA, sub-processor list, residency options and control documentation are published rather than gated. If your risk team needs something that is not on this page, ask security@shadowmap.com and you will get a direct answer.